SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Large Language Models (LLMs) such as ChatGPT, Claude, and Grok have become very powerful. This talk is full of live demonstrations of the kinds of things information security professionals can do with the LLMs. Examples include analyzing and manipulating shell code, writing exfiltration code, analyzing logs, and more.
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About Cyber Defense NetWars: Focused on preventing, analyzing, and defending against complex real-world attack scenarios, including brute-force attacks and ransomware campaigns.
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About Cyber Defense NetWars: Focused on preventing, analyzing, and defending against complex real-world attack scenarios, including brute-force attacks and ransomware campaigns.
Actionable intelligence is only as good as your ability to share it — quickly, reliably, and with the right context. In this talk, we’ll explore how MISP can be used not just as a threat intel repository, but as a powerful engine for real-time collaboration and operational impact. We’ll cover how to make MISP highly available, build and sustain a community around it, and create qualitative events that provide the necessary context for detection, decision-making, and response. You’ll also see how we’re integrating AI into our workflows to improve speed, reduce manual effort, and enrich intelligence automatically — without sacrificing quality. Whether you’re just getting started with MISP or looking to take your threat sharing to the next level, this talk will give you concrete ideas to make it work in high-pressure, real-world environments.
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.
In Digital Forensics, Incident Response, and other Cyber Security topics, we're frequently tasked with consuming HUGE amounts of data and finding the "interesting" parts quickly. We've had great tools to do this for decades. But, those tools we're optimized for old computing hardware. In our modern day we have setups with multiple CPU cores and flash storage. This talk will present some techniques to speed up those old techniques fully utilizing modern hardware.
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About Core NetWars: The most comprehensive of the NetWars ranges, this ultimate multi-disciplinary cyber range powers up the most diverse cyber skills. This range is ideal for advancing your cybersecurity prowess in today's dynamic threat landscape. The winning team and the top five solo players from every Core NetWars tournament throughout the year are offered a chance to compete in the annual SANS Core NetWars Tournament of Champions.
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About Core NetWars: The most comprehensive of the NetWars ranges, this ultimate multi-disciplinary cyber range powers up the most diverse cyber skills. This range is ideal for advancing your cybersecurity prowess in today's dynamic threat landscape. The winning team and the top five solo players from every Core NetWars tournament throughout the year are offered a chance to compete in the annual SANS Core NetWars Tournament of Champions.